Incident Investigation

AI Triage vs Supervisor Review vs Formal Investigation: Which Route Fits a Safety Signal?

A decision comparison for EHS leaders choosing how to route safety signals without letting automation replace judgment or let serious risk wait in a queue.

By 6 min read

Key takeaways

  1. 01AI triage is best for sorting and prioritizing information, not for deciding whether work is safe to continue.
  2. 02Supervisor review adds live context, but it only works when the supervisor has authority to pause, correct, and escalate work.
  3. 03Formal investigation fits serious events, high-potential near misses, repeated failures, and cases that require protected evidence.
  4. 04Consequence, evidence, and authority should determine the route, rather than the convenience of the reporting tool.
  5. 05The strongest system connects all three routes with explicit handoffs and human review points.

Safety-signal routing is the decision about what should happen after a concern, near miss, observation, or incident enters the system. AI triage can sort information, a supervisor review can test the immediate work context, and a formal investigation can examine underlying causes. None of the three is automatically the right first move.

The difficult question is not whether a site should use artificial intelligence. It is whether the route preserves the evidence and authority needed for the consequence of the signal. A low-consequence observation may need fast classification, while a high-potential event needs protected evidence and a person with authority to change the work.

On the Headline Podcast, we keep returning to that distinction because a polished workflow can still make risk slower to see. The route should match the signal's potential, not the convenience of the reporting tool. The related article AI in EHS: 8 Decisions Executives Must Own explores the governance questions that sit behind the choice.

OSHA's incident-investigation guidance asks employers to look beyond the immediate trigger and identify underlying system causes. NIST's Artificial Intelligence Risk Management Framework asks organizations to govern, measure, and manage AI risk with defined human roles. Together, those sources support a practical rule for EHS teams. Automation may help route a signal, but it should not silently decide the level of protection required.

What should determine the route?

Three criteria separate a useful workflow from a digital intake queue. The first is consequence, meaning what could happen if the signal represents a real exposure. The second is evidence, meaning how much information is available and how quickly it may disappear. The third is authority, meaning who can pause work, preserve records, interview people, or fund a control change.

These criteria matter because the same report label can hide different realities. A “minor equipment issue” may describe a cosmetic defect, or it may be the last visible sign of a failed barrier before a serious event. Classification is therefore a starting point, not a conclusion.

CriterionAI triageSupervisor reviewFormal investigation
Best useSort and prioritize incoming informationTest the current work contextExamine causes and prevent recurrence
Primary strengthSpeed and consistency of routingProximity to the workProtected evidence and deeper analysis
Primary riskFalse confidence in classificationNormalization of local workaroundsDelay or excessive bureaucracy
Required authorityDefined escalation rulesPermission to pause and correctAuthority to investigate and resource controls

Option 1: AI triage for speed and consistency

AI triage is useful when the organization receives more signals than a small team can classify quickly. A model can identify repeated terms, group similar reports, flag missing fields, and direct an item toward a defined human queue. It can also make the first response more consistent when different supervisors apply different labels to similar reports.

That value is administrative and analytical. It does not mean the model understands the task as a worker experienced it, or that it can judge whether a control is truly holding in the field. A model sees the information supplied to it, including the omissions and language choices that shaped the report.

NIST's AI Risk Management Framework is useful here because it places governance around the system rather than treating the model as a neutral appliance. The site needs an owner for the model, a defined purpose, a review route for disputed classifications, and a record of what the system did with each signal.

AI triage fits when the decision is “where should this information go next?” It does not fit as the only answer to “is work safe to continue?” A high-potential signal should be escalated by rule even when the model expresses low confidence, because uncertainty is itself a reason for human review.

Option 2: Supervisor review for immediate context

A supervisor review is the fastest way to reconnect a report with the work that produced it. The supervisor can see the task, speak with the crew, check whether the condition is still present, and decide whether a temporary control is enough to keep people protected while a deeper review begins.

That proximity is a strength only when the supervisor has real decision rights. If the role can record a concern but cannot pause production, call EHS, isolate equipment, or reject an unsafe restart, the review becomes an observation with no control consequence.

Local knowledge can also create a blind spot. Supervisors who have lived with a workaround may recognize it instantly but no longer see it as abnormal. James Reason's work on latent conditions helps explain why a visible action by one person may be connected to a design, planning, or resource condition that sits outside the work area.

Supervisor review fits when the signal needs immediate field verification and the potential consequence is still being clarified. It should trigger formal escalation when the concern involves serious injury potential, repeated control failure, conflicting accounts, a significant change in work, or evidence that the local team cannot resolve the exposure within its authority.

Option 3: Formal investigation for consequence and learning

A formal investigation is the right route when the organization needs to preserve evidence, establish a defensible causal account, or determine why a control failed. OSHA describes incident investigation as a way to identify and control underlying causes, rather than stopping at the immediate action or the person closest to the event.

The formal route should begin early enough to protect evidence. Photographs, equipment condition, permits, logs, work instructions, and witness memory can all change after the event. Waiting for a convenient meeting date can make the final report sound complete while leaving the most important facts uncertain.

Formal does not have to mean slow. A site can define thresholds that start an evidence-preservation response immediately, then scale the investigation team to the consequence and complexity. The key is to separate the urgency of protecting evidence from the time required to complete the analysis.

This route fits serious incidents, high-potential near misses, repeated events, barrier failures, and cases in which the initial account does not explain the exposure. It is also appropriate when the organization needs to test whether corrective actions changed the work rather than merely closed an action field.

How the three routes compare under pressure

Leaders often frame the choice as technology versus people. That framing is too simple. The real comparison is between different kinds of work. AI triage organizes information, supervisor review tests the live context, and formal investigation builds an evidence-based explanation. A mature system uses them as connected stages when the signal requires more than one.

AI triage wins on volume. It can help a central team see patterns that would remain scattered across emails, forms, and shift notes. Its output should be treated as a recommendation with traceable reasoning, not as a safety clearance.

Supervisor review wins on immediacy. It can answer questions that no dashboard can answer, including whether the task is still underway, whether the control is available, and whether the crew understands the change. Its weakness appears when production pressure, familiarity, or limited authority shapes the conclusion.

Formal investigation wins on consequence. It creates the space to examine system conditions, compare evidence, challenge the first story, and assign control ownership. Its weakness appears when every report is forced through the same process, because over-investigation delays action on simple problems and teaches people that reporting creates paperwork.

Decision needPreferred first routeEscalation trigger
Classify a large incoming queueAI triageLow confidence, high-potential language, or missing context
Confirm whether exposure is still activeSupervisor reviewWork cannot be made safe within local authority
Protect evidence after a serious eventFormal investigationAny uncertainty that could change the prevention decision
Detect repeated weak signalsAI triage plus human pattern reviewRecurring signal with no effective control change
Test whether a corrective action workedSupervisor review plus formal verificationField evidence contradicts closure status

Recommendation for an EHS leader

Do not select one route as the universal owner. Design a routing architecture in which each route has a narrow job, a clear handoff, and a human decision point. The architecture should make it difficult for an automated low-severity label to suppress a high-consequence signal, and it should make it equally difficult for a formal investigation queue to delay a simple control correction.

Start with four rules. First, define consequence-based escalation terms that override the model's ranking. Second, give supervisors written authority to pause work and call for help. Third, preserve the original report, model output, human decision, and later reclassification in one evidence trail. Fourth, review false negatives and false positives as a governance problem, not as an individual blame exercise.

The most important test is visible in the field. If people can see that a signal reached a decision, the route is building trust. If reports disappear into a queue, the site is collecting information without creating protection. As the Headline Podcast conversation around leadership and safety keeps showing, the quality of a system is measured by what changes after someone tells the truth.

When a signal could represent serious exposure, protect people and evidence before optimizing the workflow. Speed matters, but the wrong fast decision can make the next event harder to prevent.

Headline Podcast brings leaders and safety practitioners into the same conversation so operational decisions become clearer before pressure makes them invisible. Explore the podcast and continue the discussion.

Topics incident-investigation ai-in-ehs safety-signals supervisor-review root-cause-analysis risk-escalation headline-podcast

Frequently asked questions

Should AI decide whether a safety signal is serious?
No. AI can help classify and prioritize information, but a defined human role should decide the response when consequence, uncertainty, or missing evidence could affect worker protection.
When is supervisor review enough?
Supervisor review may be enough when the concern is limited, the exposure can be verified immediately, and the supervisor has authority to correct and confirm the control. Repetition, high potential, or unresolved uncertainty should trigger escalation.
When should a near miss become a formal investigation?
A near miss should enter formal investigation when it had serious-injury potential, exposed a failed barrier, repeated an earlier pattern, involved significant change, or cannot be explained by the initial account.
How can leaders audit AI triage?
Keep the original report, the model classification, the human decision, the escalation path, and the later outcome. Review cases where humans changed the classification and look for patterns in missed or delayed escalation.
What is the main mistake in safety-signal routing?
The main mistake is treating one route as universal. A queue can be fast but shallow, a supervisor can be close but normalized to local workarounds, and a formal investigation can be rigorous but too slow for an active exposure.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI